// For flags

CVE-2009-0802

 

Severity Score

5.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

Qbik WinGate, cuando el modo de intercepción transparente esta activado, utiliza una cabecera de Host HTTP para determinar un punto final remoto, lo que permite a atacantes remotos evitar el control de acceso para Flash, Java, Silverlight y probablemente otras tecnologías, y posiblemente comunicar con sitios restringidos de redes internas a través de una pagina web manipulada que causa que el cliente envíe peticiones HTTP con una cabecera host modificada.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-03-04 CVE Reserved
  • 2009-03-04 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.0.0
Search vendor "Qbik" for product "Wingate" and version "6.0.0"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.0.1_build_993
Search vendor "Qbik" for product "Wingate" and version "6.0.1_build_993"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.0.1_build_995
Search vendor "Qbik" for product "Wingate" and version "6.0.1_build_995"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.0.2_build_1000
Search vendor "Qbik" for product "Wingate" and version "6.0.2_build_1000"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.0.2_build_1001
Search vendor "Qbik" for product "Wingate" and version "6.0.2_build_1001"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.0.3_build_1005
Search vendor "Qbik" for product "Wingate" and version "6.0.3_build_1005"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.1
Search vendor "Qbik" for product "Wingate" and version "6.1"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.1.1.1077
Search vendor "Qbik" for product "Wingate" and version "6.1.1.1077"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.1.2
Search vendor "Qbik" for product "Wingate" and version "6.1.2"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.1.3
Search vendor "Qbik" for product "Wingate" and version "6.1.3"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.1.4
Search vendor "Qbik" for product "Wingate" and version "6.1.4"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.2
Search vendor "Qbik" for product "Wingate" and version "6.2"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.2.1
Search vendor "Qbik" for product "Wingate" and version "6.2.1"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.2.2
Search vendor "Qbik" for product "Wingate" and version "6.2.2"
-
Affected
Qbik
Search vendor "Qbik"
Wingate
Search vendor "Qbik" for product "Wingate"
6.5.2
Search vendor "Qbik" for product "Wingate" and version "6.5.2"
-
Affected